<a id="cas-openid-connect-via-apereo-cas"></a>

# CAS (OpenID Connect via Apereo CAS)

<a id="backend-class"></a>

## Backend class

For Django, add this class path to `AUTHENTICATION_BACKENDS`. For other
integrations, use the same class path in the framework-specific backend
setting.

| Backend name   | Class path                                      |
|----------------|-------------------------------------------------|
| `cas`          | `social_core.backends.cas.CASOpenIdConnectAuth` |

The [CAS](https://apereo.github.io/cas/6.6.x/authentication/OIDC-Authentication.html) backend allows authentication against an Apereo CAS OIDC provider.
The backend class is CASOpenIdConnectAuth with name cas.  A minimum
configuration is:

```default
SOCIAL_AUTH_CAS_OIDC_ENDPOINT = 'https://.....'
SOCIAL_AUTH_CAS_KEY = '<client_id>'
SOCIAL_AUTH_CAS_SECRET = '<client_secret>'
```

The remaining configuration will be auto-detected, by fetching:

```default
<SOCIAL_AUTH_CAS_OIDC_ENDPOINT>/.well-known/openid-configuration
```

This class functions identically to the generic OIDC backend, but hides
the differences in implementation details of the OIDC implementation in
Apereo CAS.

<a id="user-identification"></a>

## User identification

Accounts are associated by the OpenID Connect `sub` claim. Associations
created by older social-core releases used the normalized username and migrate
on the next successful authentication.

Note that despite the naming of the backend, this is NOT an implementation
of the CAS protocol, also supported by Apereo CAS. The CAS backend is only
intended as a way to use the Apereo CAS identity provider as an
authentication service, but via OIDC.

<a id="username"></a>

## Username

The [CAS](https://apereo.github.io/cas/6.6.x/authentication/OIDC-Authentication.html) backend will check for a `preferred_username` key in the values
returned by the server.  If the username is under a different key, this can
be overridden:

```default
SOCIAL_AUTH_CAS_USERNAME_KEY = 'nickname'
```

This setting indicates that the username should be populated by the
`nickname` claim instead.

<a id="scopes"></a>

## Scopes

The default set of scopes requested are “openid”, “profile” and “email”.
You can request additional claims, for example:

```default
SOCIAL_AUTH_CAS_SCOPE = ['groups']
```

and you can prevent the inclusion of the default scopes using:

```default
SOCIAL_AUTH_CAS_IGNORE_DEFAULT_SCOPE = True
```

<a id="external-memberships"></a>

## External memberships

See [External groups](../groups.html.md) for opt-in extraction, group-based login restrictions, and
local group synchronization. No separate extraction pipeline step is needed.
